UTSA
Amy(Yun) Zhang, Ram Krishnan, Ravi Sandhu Institute for Cyber Security University of Texas at San Antonio San Antonio, TX 78249 Nov 03, 2014
UTSA Information Sharing and Coordination Initiatives - - PowerPoint PPT Presentation
Secure Information and Resource Sharing in Cloud Infrastructure as a Service Cyber Incident Response Models for Information and Resource Sharing Amy(Yun) Zhang, Ram Krishnan, Ravi Sandhu Institute for Cyber Security University of Texas at San
Amy(Yun) Zhang, Ram Krishnan, Ravi Sandhu Institute for Cyber Security University of Texas at San Antonio San Antonio, TX 78249 Nov 03, 2014
2
Ref: http://www.whitehouse.gov/issues/foreign-policy/cybersecurity/national-initiative
3
4
6
7
8
Participant B
Secure Isolated Domain (SID)
Add/Remove Data Join/Leave Users Add/Remove Data Join/Leave Users Add/Remove Data Join/Leave Users
View #1: Org C View #1: Org B View #1: Org A Participant C Participant A
9
View #2: SID View #2: SID View #2: SID Can create multiple secure isolated projects (SIPs) within SID with different controls
> 200 companies ~14000 developers >130 countries 10
Ref: http://www.openstack.org
11
12
13
ORG A ORG B
Establish/Disband Join User Join User Leave User Leave User Remove Version Merge Version Substitute User Add Version Remove Version Merge Version Substitute User Create RO/RW Subject Kill Subject Create Object Read/Update Version Suspend/Resume Version
Collaboration Group
Create RO/RW Subject Kill Subject Create Object Read/Update Version Suspend/Resume Version
Administrative Model Operational Model
Add Version Import Version
14
15
16
SAWS
Admin: SAWSadmin
Users: Harry@SAWS IT-SAWS
member
SAPD
Admin: SAPDadmin
Users: Martin@SAPD IT-SAPD
member member member Create Join Share objects, VMs, etc.
CPS
Admin: CPSadmin
Users: Alice@CPS, Bob@CPS IT-CPS
member
SID-Critical-Infrastructure
SIP- PortScanning SIP-DOS
Users: Alice@CPS, Harry@SAWS
Admins:
CPSadmin, SAWSadmin
– Formal specification
– Cyber incident response capabilities
– Practitioners can deploy a “cyber incident response” cloud – Potential blueprint for official OpenStack adoption
– more fine grained access control within a SIP – harden the implementation to prevent overt information flow
17
18